Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

FL SWITCH 2005 — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in FL SWITCH 2005, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses and vulnerabilities associated with the FL SWITCH 2005 industrial Ethernet switch, categorized under general hardware and firmware security tags. It aggregates data from various sources to provide a comprehensive overview of the risks affecting this specific network device. The content includes a range of vulnerability types, such as buffer overflows, input validation errors, and authentication bypass flaws, covering the period from the product's initial release through recent updates. By centralizing this information, the page allows security professionals and network administrators to effectively track vendor advisories and patch releases related to FL Systems' industrial communication equipment. Users can explore how different weakness classes manifest within the product’s architecture, gaining deeper insight into the specific attack vectors and mitigation strategies. Additionally, the historical view of vulnerabilities aids in assessing the long-term security posture and maintenance practices of the device. This resource serves as a critical reference for understanding the cumulative risk landscape, enabling informed decision-making regarding deployment, configuration, and lifecycle management. It supports compliance audits and security assessments by providing a clear, aggregated record of past issues and their resolutions. The goal is to enhance visibility into the operational security environment of FL SWITCH 2005 deployments across critical infrastructure sectors.

Vendor: Phoenix Contact

CVE IDTitleCVSSSeverityPublished
CVE-2026-22323 Cross‑Site Request Forgery in Link Aggregation Configuration CWE-352 7.1 High2026-03-18
CVE-2026-22322 Stored Cross‑Site Scripting in Link Aggregation Name Handling CWE-79 7.1 High2026-03-18
CVE-2026-22321 Stack-Based Buffer Overflow in CLI Login Username Handling over CLI CWE-121 5.3 Medium2026-03-18
CVE-2026-22320 Stack-Based Buffer Overflow in TFTP File-Transfer Command Handling over CLI CWE-121 6.5 Medium2026-03-18
CVE-2026-22319 Stack-Based Buffer Overflow in File Install Parameter Handling CWE-121 4.9 Medium2026-03-18
CVE-2026-22318 Stack-Based Buffer Overflow in File Transfer Parameter Handling CWE-121 4.9 Medium2026-03-18
CVE-2026-22317 Command Injection Vulnerability in Root CA Certificate Transfer Workflow CWE-77 7.2 High2026-03-18
CVE-2026-22316 Buffer Overflow using TFTP Filename CWE-121 6.5 Medium2026-03-18
CVE-2025-41693 Authenticated Denial-of-Service via SSH CWE-770 4.3 Medium2025-12-09
CVE-2025-41696 Hardcoded User Password CWE-798 4.6 Medium2025-12-09
CVE-2025-41694 Authenticated Denial-of-Service via Webshell CWE-770 6.5 Medium2025-12-09
CVE-2025-41692 Weak/Predictable root Password CWE-916 6.8 Medium2025-12-09
CVE-2025-41697 Shell access to UART Console CWE-1299 6.8 Medium2025-12-09
CVE-2025-41695 Reflected XSS vulnerability in dyn_conn.php CWE-79 7.1 High2025-12-09
CVE-2025-41745 Reflected XSS vulnerability in pxc_portCntr2.php CWE-79 7.1 High2025-12-09
CVE-2025-41746 Reflected XSS vulnerability in pxc_portSecCfg.php CWE-79 7.1 High2025-12-09
CVE-2025-41747 Reflected XSS vulnerability in pxc_vlanIntfCfg.php CWE-79 7.1 High2025-12-09
CVE-2025-41748 Reflected XSS vulnerability in pxc_Dot1xCfg.php CWE-79 7.1 High2025-12-09
CVE-2025-41749 Reflected XSS vulnerability in port_util.php CWE-79 7.1 High2025-12-09
CVE-2025-41750 Reflected XSS vulnerability in pxc_PortCfg.php CWE-79 7.1 High2025-12-09
CVE-2025-41751 Reflected XSS vulnerability in pxc_portCntr.php CWE-79 7.1 High2025-12-09
CVE-2025-41752 Reflected XSS vulnerability in pxc_portSfp.php CWE-79 7.1 High2025-12-09

All 22 known CVE vulnerabilities affecting FL SWITCH 2005 with full Chinese analysis, references, and POCs where available.